Change log for PROOFPOINT_TRAP

Date Changes
2025-06-04 Enhancement:
- event.idm.read_only_udm.network.email.mail_id: Newly mapped `event1.description.messageid` raw log field with `event.idm.read_only_udm.network.email.mail_id` UDM field.
- event.idm.read_only_udm.principal.ip: Newly mapped `sender IP` extracted from `event1.description.headers.Authentication-Results` raw log field with grok and mapped to `event.idm.read_only_udm.principal.ip` and `event.idm.read_only_udm.principal.asset.ip` UDM field.
- event.idm.read_only_udm.principal.user.userid: Newly mapped `event1.description.sender.email` raw log field with `event.idm.read_only_udm.principal.user.userid` UDM field.
- event.idm.read_only_udm.target.user.email_addresses: Newly mapped `event1.description.recipient.email` raw log field with `event.idm.read_only_udm.target.user.email_addresses` UDM field.
- event.idm.read_only_udm.network.email.subject: Newly mapped `event1.description.subject` raw log field with `event.idm.read_only_udm.network.email.subject` UDM field.
- event.idm.read_only_udm.metadata.event_timestamp: Newly mapped `event1.description.created_at` raw log field with `event.idm.read_only_udm.metadata.event_timestamp` UDM field.
- event.idm.read_only_udm.metadata.collected_timestamp: Newly mapped `event1.description.updated_at` raw log field with `event.idm.read_only_udm.metadata.collected_timestamp` UDM field.
- event.idm.read_only_udm.metadata.product_log_id: Newly mapped `event1.description.id` raw log field with `event.idm.read_only_udm.metadata.product_log_id` UDM field.
- event.idm.read_only_udm.sec_result.detection_fields: Newly mapped `event1.description.headers.From` raw log field with `event.idm.read_only_udm.sec_result.detection_fields` UDM field.
- event.idm.read_only_udm.network.email.to: Newly mapped `event1.description.headers.To` raw log field with `event.idm.read_only_udm.network.email.to` UDM field.
- event.idm.read_only_udm.network.email.reply_to: Newly mapped `event1.description.headers.Reply-To` raw log field with `event.idm.read_only_udm.network.email.reply_to` UDM field.
- event.idm.read_only_udm.sec_result.description: Newly mapped `event1.description.headers.Received-SPF` raw log field with `event.idm.read_only_udm.sec_result.description` UDM field.
- event.idm.read_only_udm.sec_result.detection_fields: Newly mapped `event1.description.headers.DKIM-Signature` raw log field with `event.idm.read_only_udm.sec_result.detection_fields` UDM field.
- event.idm.read_only_udm.principal.user.attribute.labels: Newly mapped `event1.description.sender.vap` raw log field with `event.idm.read_only_udm.principal.user.attribute.labels` UDM field.
- event.idm.read_only_udm.target.user.attribute.labels: Newly mapped `event1.description.recipient.vap` raw log field with `event.idm.read_only_udm.target.user.attribute.labels` UDM field.
- event.idm.read_only_udm.intermediary.labels: Newly mapped `event1.description.hosts.url` raw log field with `event.idm.read_only_udm.intermediary.labels` UDM field.
- event.idm.read_only_udm.security_result.detection_fields: Newly mapped `event1.description.urls` raw log field with `event.idm.read_only_udm.security_result.detection_fields` UDM field.
- event.idm.read_only_udm.sec_result.severity: Newly mapped `event1.description.severity` raw log field with `event.idm.read_only_udm.sec_result.severity` UDM field.
- event.idm.read_only_udm.sec_result.summary: Newly mapped `event1.description.state` raw log field with `event.idm.read_only_udm.sec_result.summary` UDM field.
2025-02-20 Enhancement:
- Added support for parsing additional fields.
2025-01-29 Enhancement:
- Mapped "mailfrom", "spf", "dkim1", "header_s1", "header_d1", "dkim2", "header_s2", "header_d2", and "dmarc" to "security_result.detection_fields".
- Mapped "send_email" to "network.email.from".
- Mapped "to_email" to "network.email.to".
2025-01-14 Enhancement:
- Defined labels inside the for loop.
2024-12-12 Enhancement:
- Added support for the new pattern of JSON logs.
2024-09-11 Enhancement:
- When "proofpoint_trap_host" is a valid IP then mapped it to "intermediary.ip". Otherwise, mapped it to "intermediary.ip".
- Mapped "users" to "principal.user.userid".
- Mapped "received" to "metadata.event_timestamp".
- Added support for JSON logs.
2024-06-05 Enhancement:
- Added support for JSON logs.
2023-05-26 Added mapping for the following fields:
- "ewsUrl" mapped to "principal.url".
- "username" mapped to "principal.user.user_display_name".
- "exchangeAuthType","exchangeAPI","tenantId","clientId","clientSecret","graphApiEndpoint","alternateGraphApiEndpoint",
"azureAdAuthEndpoint","privateKey" mapped to "additional.fields".
2022-08-23 Newly Created Parser